AgentsBitdefender MCP Security — 53% Static Credentials, 8.5% OAuthBitdefender·high signalXBlueskyLinkedInCopy linkFive key MCP risk categories. CVE-2025-6514 CVSS 9.6 RCE, CVE-2025-32711 EchoLeak. 53% open-source MCP servers use insecure static credentials, only 8.5% use OAuth.SourceSource pageBitdefender↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Policy dependency / Stack layerPattern: the agent config layer is being treated as an unmanaged dependency graph, and three independent sources said so this weekarXivStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivPolicy dependency / Stack layerMemSentry gates persistent memory writes on a signed security-state delta rather than on content classificationarXivPolicy dependency / Stack layerAnthropic Gave EU Cybersecurity Agency ENISA Access to Mythos 5, Three Months After Release, and Still Withholds 5.1BloombergStack layer / Threat patternClaude Code 2.1.265 Ships a 1 GB Tool-Result Cap and Three Prompt-Cache Reuse Fixes, Then 2.1.266 Reverts a Gateway Regression Hours LaterAnthropic (claude-code CHANGELOG)Stack layer / Threat patternCline Desktop 0.0.25 lets Claude Code and Codex CLI providers start sessions with no API key, and caps Codex models at real backend budgetsGitHub ReleasesStack layer / Threat patternGoogle's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session ReplayOffSeq Threat Radar